Resume

Cybersecurity governance, risk, and assessment leadership.

Twelve years across healthcare, government, higher education, and enterprise technology. Former BISO who owned cybersecurity GRC for around 150 applications and drove vulnerability-remediation SLA compliance from 65% to 99%.

Experience translating security risk into action.

  • Owned cybersecurity GRC for around 150 applications, including 30 business-critical systems handling PHI, PII, and PCI DSS data, with monthly director and quarterly VP reporting.
  • Rebuilt a stalled vulnerability-remediation program through ownership, recurring reviews, exception governance, and leadership escalation, turning chronic SLA misses into sustained compliance.
  • Cut one third party's aged high and medium-severity findings from about 30 to under 10 through triage, remediation tracking, and evidence collection.
  • Project manager for security, privacy, and data governance on a statewide data-modernization program spanning 111 law enforcement agencies and 5 vendors.

Where I tend to be most useful

Security assessment Risk analysis Vulnerability management GRC Exception management Third-party risk Data security Executive reporting Program maturity Cloud security governance AI security governance

CISSP, CCSK, and graduate computer science background.

My background combines security leadership, cloud security knowledge, and technical program delivery, supported by CISSP, CCSK, a master's degree in Computer Science, and additional vendor security training.

View credentials